1. Organisation and DPO contact
The GrantGo SG service operator is responsible for personal data handled through the service. Submit privacy requests, data-protection questions or complaints through the public Feedback & questions channel. Do not include unnecessary sensitive information in the initial message; we may verify identity before acting on a request.
2. Scope and data collected
The service is intended for businesses and authorised representatives aged 18 or older, not children or personal/household use. We collect account and contact email; authentication and session records; business eligibility answers (which may include entity name and UEN); questionnaire answers and uploaded/generated documents; purchase, Stripe customer/payment references and refund status (not full card numbers); rejection evidence; feedback; consent records; fixed funnel event counters; and technical/security logs such as IP address, device/browser information and timestamps.
Do not submit NRIC numbers, director/shareholder names, special-category information, or unnecessary third-party personal data. If you provide another person’s data, you confirm you are authorised and have given any required notice.
3. Purposes and consent
We collect, use and disclose data to provide eligibility assessments and accounts; authenticate magic links; create, review, store and deliver documents; process purchases and refunds; provide support and transactional messages; send separately requested grant-rule updates; secure, troubleshoot and prevent abuse; maintain audit and transaction records; operate and improve the reliability and usability of the requested service; comply with law; and establish or defend legal claims. We apply purpose limitation and data minimisation: personal data is not sold, used for advertising, or reused for an unrelated independent purpose.
Where the PDPA requires consent, we notify you of the purposes and obtain consent before collection, use or disclosure. We may also process data without consent where an applicable PDPA exception permits or requires it. Refusing necessary data may prevent us from providing the requested feature. Where the GDPR applies, we rely as appropriate on steps requested before a contract, performance of a contract, legal obligations, legitimate interests in security and service operation, or consent, and apply the GDPR principles of lawfulness, fairness, transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity and accountability.
4. Disclosures and overseas transfers
We disclose data only as reasonably needed to processors such as Supabase (authentication, database and storage), Vercel (hosting), Stripe (payments/refunds), transactional email providers, and OpenAI or Anthropic for AI-assisted narrative generation, plus professional advisers, authorities or a successor in a lawful business transfer. Providers act under their own terms and/or our instructions.
Some recipients or infrastructure may be outside Singapore. A transfer is made only where the PDPA transfer-limitation requirements are satisfied, including through contractual or other legally recognised safeguards where required, or where a lawful exception applies. Provider locations and the safeguard used can vary; contact the DPO for current details and, where the GDPR applies, how to obtain a copy of the relevant safeguard.
5. Cookies and analytics
We use cookies and similar storage necessary for authentication, security, magic-link sessions and continuity of the eligibility check. We currently use fixed, pseudonymous per-tab funnel counters (check started and self-declaration reached) rather than third-party advertising analytics; raw counter rows are pruned after 7 days. If optional analytics or advertising cookies are introduced, this notice and consent controls will be updated before use where required.
6. Retention and deletion
We keep personal data only as long as reasonably needed for the stated purposes or legal or business requirements, then delete or anonymise it. Stored generated-document files, including rendered document-version files, are scheduled for deletion 30 days after generation; related database records may remain without the deleted file. Signed download links expire after 24 hours. Funnel events are retained for 7 days and Stripe webhook-ledger rows for 90 days. Account, assessment, transaction, rejection-evidence and refund records otherwise remain while the account is active and for as long as needed for support, accounting, disputes, fraud prevention or legal obligations, and are reviewed when those purposes cease.
Authenticated users can request account deletion from the account page. The cascade deletes profiles, assessments, matches, questionnaires, generated documents/versions, job records, refund requests/evidence, subscriptions and related storage. Stripe and other independent recipients may retain records under their own legal obligations. Backups may take a limited period to cycle out and are not restored for ordinary use.
7. Individual rights and withdrawal
You may request access to personal data we hold and information about its use/disclosure in the preceding year, or request correction, subject to PDPA exceptions. We will verify identity, respond as soon as reasonably possible, and may charge only a permitted reasonable fee after giving an estimate. You may withdraw consent with reasonable notice by contacting the DPO; rule-update email consent can also be withdrawn using the unsubscribe link. Withdrawal does not affect prior lawful processing and may prevent continued service.
Where the GDPR applies, you may also have rights to erasure, restriction, data portability and objection, and to complain to the competent EU or EEA supervisory authority, subject to the GDPR’s conditions and exceptions. Eligibility assessments use rules-based automated processing to provide guidance, but GrantGo SG does not make a decision that itself grants, refuses or determines legal entitlement to government funding; the administering agency makes that decision.
8. Accuracy and protection
Please keep information accurate and notify us of corrections. We use reasonable administrative, technical and physical safeguards, including access controls, encrypted transport, private storage, short-lived download links, input validation and minimised logging. No system is completely secure; protect your email account and magic links.
9. Data incidents
We assess suspected breaches and take containment and remediation steps. Where a breach is notifiable under the PDPA, we will notify the Personal Data Protection Commission as soon as practicable and no later than three calendar days after determining it is notifiable, and notify affected individuals as soon as practicable where required.
10. Complaints and changes
Direct privacy questions or complaints to the DPO. We will investigate and respond in good faith; you may also contact the PDPC. We may update this notice prospectively and will identify the new date and reasonably notify material changes. Use of the service after an update does not override any consent required by law.